CVE-2025-5520

Source
https://cve.org/CVERecord?id=CVE-2025-5520
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-5520.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-5520
Published
2025-06-03T18:00:22.302Z
Modified
2026-07-22T00:05:46.933735Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Open5GS AMF/MME emm_state_authentication assertion
Details

A vulnerability was found in Open5GS up to 2.7.3. It has been classified as problematic. Affected is the function gmmstateauthentication/emmstateauthentication of the component AMF/MME. The manipulation leads to reachable assertion. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 9f5d133657850e6167231527514ee1364d37a884. It is recommended to apply a patch to fix this issue. This is a different issue than CVE-2025-1893.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/5xxx/CVE-2025-5520.json",
    "cwe_ids": [
        "CWE-617"
    ],
    "cna_assigner": "VulDB",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "2.7.3"
                },
                {
                    "last_affected": "2.7.3"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/open5gs/open5gs

Affected ranges

Type
GIT
Repo
https://github.com/open5gs/open5gs
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "2.7.0"
        },
        {
            "last_affected": "2.7.0"
        },
        {
            "introduced": "2.7.1"
        },
        {
            "last_affected": "2.7.1"
        },
        {
            "introduced": "2.7.2"
        },
        {
            "last_affected": "2.7.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.7.0
2.7.1
2.7.2
v2.*
v2.7.0
v2.7.1
v2.7.2
v2.7.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-5520.json"
vanir_signatures_modified
"2026-07-22T00:05:46Z"
vanir_signatures
[
    {
        "digest": {
            "function_hash": "83500632070580911998797047966065524410",
            "length": 8423.0
        },
        "id": "CVE-2025-5520-0ef524c2",
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_type": "Function",
        "target": {
            "function": "gmm_state_security_mode",
            "file": "src/amf/gmm-sm.c"
        }
    },
    {
        "digest": {
            "function_hash": "160781599133266726046446224547111322076",
            "length": 7169.0
        },
        "id": "CVE-2025-5520-3a05cf93",
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_type": "Function",
        "target": {
            "function": "gmm_state_exception",
            "file": "src/amf/gmm-sm.c"
        }
    },
    {
        "digest": {
            "function_hash": "22859958192396035505212974093563823443",
            "length": 4124.0
        },
        "id": "CVE-2025-5520-6869893c",
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_type": "Function",
        "target": {
            "function": "emm_state_authentication",
            "file": "src/mme/emm-sm.c"
        }
    },
    {
        "digest": {
            "line_hashes": [
                "162612948853236519870417624286336986397",
                "279800737103072097352342639440643898857",
                "224344108714082424795084970797513107060",
                "92174190948770943019300478285797406489",
                "11496801759268304833503557185898646113",
                "279800737103072097352342639440643898857",
                "63600953943289955141616430274593087484",
                "256210522018344380583522769866622864221",
                "8531826659309212253945361217639555917",
                "279800737103072097352342639440643898857",
                "63600953943289955141616430274593087484",
                "256210522018344380583522769866622864221",
                "88933678767554333444634080757504132882",
                "279800737103072097352342639440643898857",
                "63600953943289955141616430274593087484",
                "98279082891080693496667047401417186958",
                "218423668681304689602073986062147818177",
                "279800737103072097352342639440643898857",
                "63600953943289955141616430274593087484",
                "98279082891080693496667047401417186958",
                "218423668681304689602073986062147818177",
                "287361486533403811949021440182620113055",
                "329928212348722115459337753229020731516",
                "221167672963450854736231568572233024945",
                "171710928360583683359703307818570784637"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2025-5520-7cf36230",
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_type": "Line",
        "target": {
            "file": "src/amf/gmm-sm.c"
        }
    },
    {
        "digest": {
            "function_hash": "7840338246266733304109947859179352179",
            "length": 2198.0
        },
        "id": "CVE-2025-5520-8258339c",
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_type": "Function",
        "target": {
            "function": "emm_state_exception",
            "file": "src/mme/emm-sm.c"
        }
    },
    {
        "digest": {
            "line_hashes": [
                "181587525657022427075386250389554607630",
                "214597673683049392675310664109267682895",
                "44783538911283254919575295468980251765",
                "17076408781526451615758545393702765642",
                "181587525657022427075386250389554607630",
                "252775408427670992673771619141331972551",
                "258020227633328548922632536403702770528",
                "133599961499748681934399517810130714389",
                "181587525657022427075386250389554607630",
                "193216346956972609628193931368582367486",
                "210300223049496830621915461069147382003",
                "14486022831773130212852169467389047262",
                "181587525657022427075386250389554607630",
                "53677434448106881679034576068327455465",
                "22640183906031040781591380454654267857",
                "135300274118787480034969130986824843604"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2025-5520-888aab85",
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_type": "Line",
        "target": {
            "file": "src/mme/emm-sm.c"
        }
    },
    {
        "digest": {
            "function_hash": "116882255355674317971163153045468861679",
            "length": 9739.0
        },
        "id": "CVE-2025-5520-ad2585fe",
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_type": "Function",
        "target": {
            "function": "common_register_state",
            "file": "src/amf/gmm-sm.c"
        }
    },
    {
        "digest": {
            "function_hash": "72387096183728905946385029289657893898",
            "length": 5578.0
        },
        "id": "CVE-2025-5520-b03c51d3",
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_type": "Function",
        "target": {
            "function": "emm_state_security_mode",
            "file": "src/mme/emm-sm.c"
        }
    },
    {
        "digest": {
            "function_hash": "58969063080390576501044478447730453268",
            "length": 8629.0
        },
        "id": "CVE-2025-5520-d911ed6c",
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_type": "Function",
        "target": {
            "function": "gmm_state_initial_context_setup",
            "file": "src/amf/gmm-sm.c"
        }
    },
    {
        "digest": {
            "function_hash": "126460456160147151523067791108123358265",
            "length": 8606.0
        },
        "id": "CVE-2025-5520-f9f3436d",
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_type": "Function",
        "target": {
            "function": "gmm_state_authentication",
            "file": "src/amf/gmm-sm.c"
        }
    },
    {
        "digest": {
            "function_hash": "59366305747887547644834116805621754724",
            "length": 5436.0
        },
        "id": "CVE-2025-5520-fc955644",
        "deprecated": false,
        "signature_version": "v1",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_type": "Function",
        "target": {
            "function": "emm_state_initial_context_setup",
            "file": "src/mme/emm-sm.c"
        }
    }
]